Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,103 advisories

Loading
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect High
CVE-2026-44503 was published for Microsoft.Kiota.Abstractions (Go) May 7, 2026
MIchaelMainer Credited to MIchaelMainer
Nadav0077 Credited to Nadav0077 and igorpyan igorpyan igorpyan
Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass) Moderate
CVE-2026-73851 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
gavinbarron Credited to gavinbarron, gn00295120, and BarakSrour gn00295120 gn00295120
BarakSrour BarakSrour
Kiota: Code Generation Literal Injection High
CVE-2026-41134 was published for Microsoft.OpenApi.Kiota (NuGet) Apr 14, 2026
baywet Credited to baywet and gavinbarron gavinbarron gavinbarron
Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref High
CVE-2026-59867 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, baywet, and gavinbarron mrostamipoor mrostamipoor
baywet baywet gavinbarron gavinbarron
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName High
CVE-2026-59866 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, baywet, and gavinbarron mrostamipoor mrostamipoor
baywet baywet gavinbarron gavinbarron
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info` Critical
CVE-2026-59865 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, gavinbarron, baywet, and mohammad228 mrostamipoor mrostamipoor
gavinbarron gavinbarron baywet baywet mohammad228 mohammad228
Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions Critical
CVE-2026-59864 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, jingjingjia-ms, and baywet mrostamipoor mrostamipoor
jingjingjia-ms jingjingjia-ms baywet baywet
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF High
CVE-2026-59863 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, baywet, and gavinbarron mrostamipoor mrostamipoor
baywet baywet gavinbarron gavinbarron
Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator High
CVE-2026-59859 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
peombwa Credited to peombwa and thegr1ffyn thegr1ffyn thegr1ffyn
Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator High
CVE-2026-59862 was published for Microsoft.OpenAPI.Kiota (NuGet) Jul 24, 2026
baywet Credited to baywet
Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator High
CVE-2026-59861 was published for Microsoft.OpenAPI.Kiota (NuGet) Jul 24, 2026
baywet Credited to baywet
Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection High
CVE-2026-59860 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
thegr1ffyn Credited to thegr1ffyn, gavinbarron, and peombwa gavinbarron gavinbarron
peombwa peombwa
manus-use Credited to manus-use
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing High
GHSA-jwjp-4649-v8jp was published for SIPSorcery (NuGet) Aug 12, 2026
manus-use Credited to manus-use
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability Moderate
CVE-2026-62902 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability High
CVE-2026-62871 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability High
CVE-2026-62897 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability High
CVE-2026-70354 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability Moderate
CVE-2026-62909 was published for Microsoft.NETCore.App.Runtime.linux-arm (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability High
CVE-2026-62886 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability High
CVE-2026-62901 was published for Microsoft.NETCore.App.Runtime.linux-arm (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability Moderate
CVE-2026-62899 was published for Microsoft.NETCore.App.Runtime.linux-arm (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerability High
CVE-2026-62898 was published for Microsoft.NETCore.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
ASP.NET Core Information Disclosure Vulnerability Moderate
CVE-2021-34532 was published for Microsoft.AspNetCore.Authentication.JwtBearer (NuGet) Aug 25, 2021
ProTip! Advisories are also available from the GraphQL API